TL;DR
Staff Security Engineer (Product Security): Build, test, and harden security features for Firefox, hirify.global VPN, and other products with an accent on embedding security into the full software development lifecycle and proactive risk mitigation. Focus on designing secure solutions, performing penetration testing, and automating security testing in CI/CD pipelines to protect millions of users.
Location: Remote within the US and Canada only
Salary: CAD 116,000–171,000 depending on location
Company
hirify.global is a non-profit-backed technology company focused on building open-source software to make the internet better and more accessible for everyone.
What you will do
- Embed security into Firefox, hirify.global VPN, and other mission-critical products to safeguard millions of users.
- Integrate security throughout the software development lifecycle including threat modeling, security assessments, and automation.
- Perform security code reviews and lead penetration testing on web, mobile, and embedded applications.
- Develop and maintain automated security tests within CI/CD pipelines to catch vulnerabilities early.
- Provide security guidance and help define security policies for development teams.
- Promote hirify.global's security culture through collaboration, guidance, and education.
Requirements
- Must have 5+ years of hands-on experience in product and application security.
- Proficiency in secure coding practices, application security testing (SAST, DAST), threat modeling, and vulnerability assessment.
- Experience with languages such as Python, Go, Java, or JavaScript for automation and code review.
- Familiarity with security tools like Burp Suite, Nessus, and CI/CD automation tools.
- Strong communication and collaboration skills to influence cross-functional teams.
- Formal credentials are a plus but real-world experience and a builder’s mindset are more important.
Culture & Benefits
- Generous performance-based bonus plans.
- Comprehensive medical, dental, and vision coverage.
- Generous retirement contributions with immediate vesting.
- Quarterly wellness days and paid parental leave.
- Home office stipend and professional development budget.
- Employee referral bonus and other benefits varying by country.
Будьте осторожны: если вас просят войти в iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →